URL: <https://savannah.gnu.org/bugs/?68710>
Summary: :dinfo causes crash on macOS
Group: GNU Screen
Submitter: None
Submitted: Mon 21 Sep 2026 08:02:58 PM UTC
Category: Crash/Freeze/Infloop
Severity: 3 - Normal
Priority: 5 - Normal
Status: None
Privacy: Public
Assigned to: None
Open/Closed: Open
Discussion Lock: Unlocked
Release: 5.0.2
Fixed Release: None
Planned Release: None
Work Required: None
_______________________________________________________
Follow-up Comments:
-------------------------------------------------------
Date: Mon 21 Sep 2026 08:02:58 PM UTC By: Anonymous
I'm seeing a crash on macOS when I invoke :dinfo. The ASan report is as
follows:
=================================================================
==15398==ERROR: AddressSanitizer: stack-buffer-overflow on address
0x00016b942520 at pc 0x000104fd31b0 bp 0x00016b9422f0 sp 0x00016b941aa0
WRITE of size 504 at 0x00016b942520 thread T0
#0 0x000104fd31ac in strncpy+0x414
(libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3b1ac)
#1 0x000104545e78 in DoCommandDinfo process.c:1594
#2 0x00010453ccac in DoAction process.c:4823
#3 0x00010456695c in DoCommand process.c:5318
#4 0x000104511518 in RcLine fileio.c:308
#5 0x00010456cae0 in ColonFin process.c
#6 0x00010451a22c in InpProcess input.c:373
#7 0x00010453b560 in ProcessInput2 process.c:745
#8 0x000104508dc8 in disp_processinput display.c:2796
#9 0x0001044e86f0 in disp_readev_fn display.c:2770
#10 0x000104576044 in sched sched.c:200
#11 0x0001044bc7f8 in main screen.c:1107
#12 0x00019ef03e7c in start+0x1a1c (dyld:arm64e+0x31e7c)
Address 0x00016b942520 is located in stack of thread T0 at offset 544 in
frame
#0 0x000104545cd0 in DoCommandDinfo process.c:1591
This frame has 1 object(s):
[32, 544) 'buf' (line 6270) <== Memory access at offset 544 overflows this
variable
HINT: this may be a false positive if your program uses some custom stack
unwind mechanism, swapcontext or vfork
(longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-overflow process.c:1594 in
DoCommandDinfo
Shadow bytes around the buggy address:
0x00016b942280: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00016b942300: f1 f1 f1 f1 00 00 00 00 00 00 00 00 00 00 00 00
0x00016b942380: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00016b942400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00016b942480: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x00016b942500: 00 00 00 00[f3]f3 f3 f3 f3 f3 f3 f3 00 00 00 00
0x00016b942580: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00016b942600: f1 f1 f1 f1 f8 f2 f8 f2 f2 f2 f8 f2 f2 f2 f8 f2
0x00016b942680: f8 f2 f2 f2 f8 f3 f3 f3 00 00 00 00 00 00 00 00
0x00016b942700: 00 00 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1
0x00016b942780: 00 00 00 00 f3 f3 f3 f3 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
==15398==ABORTING
While I'm no C expert, I believe the attached patch resolves the issue. The
issue seems to be that *p++ = ' ' consumes one byte of of space without
decrementing l. So the code hands strncpy a limit that's 1 byte larger than
the space actually available.
_______________________________________________________
File Attachments:
Name: fix-dinfo-offbyone.patch Size: 289B
<https://file.savannah.gnu.org/file/fix-dinfo-offbyone.patch?file_id=58984>
AGPL NOTICE
These attachments are served by Savane. You can download the corresponding
source code of Savane at
https://savannah.gnu.org/source/savane-1405920ddbd92feb15f7ff51a95593e5d679909d.tar.gz
_______________________________________________________
Reply to this item at:
<https://savannah.gnu.org/bugs/?68710>
_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/
signature.asc
Description: PGP signature
